474172261 / DataProtectorLinks
A simple ransomware defender.It uses minifilter to filt "rewrite" and "delete" events in kernel.And it handles event in user mode.
☆27Updated 7 years ago
Alternatives and similar repositories for DataProtector
Users that are interested in DataProtector are comparing it to the libraries listed below
Sorting:
- ☆33Updated 4 years ago
- use crystalCPUID to identify vt-x & amd-v☆17Updated 10 years ago
- A tool to investigate the Windows device manager☆12Updated 6 years ago
- copy of tdifw lib☆10Updated 8 years ago
- Windows file system driver which allows to block access to files at run-time (C/C++, C#, WDK, SDK)☆10Updated 2 years ago
- x64 Kernel Hooks Detection☆24Updated 8 years ago
- ☆12Updated 7 years ago
- ☆29Updated 4 years ago
- Open Source Libraries Collection☆24Updated 9 years ago
- PoC of BOOST-ed _EPROCESS.VadRoot iterating☆26Updated 11 years ago
- Wow64 syscall hook☆41Updated 8 years ago
- Kernel-mode file scanner☆18Updated 7 years ago
- PE Infector/Cryptor source code☆16Updated 8 years ago
- Native Development Kit for Vista 64bit And Later, by me, Based on NDK Headers 1.0, by Alex Ionescu☆17Updated 9 years ago
- Windows Minifilter driver that redirects any I/O Request of mp3 files to a target file☆17Updated 10 years ago
- ☆14Updated 7 years ago
- The project is a demo solution for one of the anti-rootkit techniques aimed on overcoming splicers☆35Updated 8 years ago
- windows kernel File redirection☆20Updated 11 years ago
- Simple command line version of Sysinternals WinObj. Currently just lists object names and types given an object manager directory.☆21Updated 2 years ago
- Hook IDT vector 0xb2 to detect SCI in 64bit windows.☆34Updated 3 years ago
- ☆14Updated 4 years ago
- A drop-in replacement for the C++ STL for kernel mode Windows drivers. The goal is to have implementations for things like the standard a…☆32Updated 9 years ago
- Remote memory library in C++17.☆33Updated 7 years ago
- ☆17Updated 8 years ago
- An API Monitor based on Instrumentation☆44Updated 7 years ago
- just an lite AntiRootkit for interesting☆24Updated 9 years ago
- Final Transparent encrypted version☆14Updated 8 years ago
- a network filter using NDIS hook technique☆19Updated 12 years ago
- it can extract functions from .dll, .exe, .sys and it be work! :)☆39Updated 6 years ago
- WhoCalls can query a directory of files, find the binaries, and search for a user specified Win API import. It and works with both 32-bit…☆18Updated 3 years ago